A fresh wave of suspected attacks targeting Coldcard hardware wallet users has drained roughly 389 Bitcoin, according to Galaxy Digital's head of research, Alex Thorn, who cautioned that some affected users may still have a slim window to rescue their funds.
What Thorn Flagged
Thorn identified what he described as a potential fourth wave of coordinated thefts hitting Coldcard wallet holders. The incidents appear to follow a similar pattern to earlier reported breaches, with attackers moving substantial sums of Bitcoin out of victims' wallets.
The scale of the latest wave is significant, with the researcher pointing to roughly 389 Bitcoin swept up in the suspected campaign. At current market values, that represents a considerable loss spread across the affected users.
Some victims may still have a narrow chance to recover their Bitcoin before pending transactions confirm on the blockchain.
A Possible Rescue Window
The key insight from Thorn's warning centers on unconfirmed transactions. Because certain outbound transfers had not yet been fully settled on the network, some users could potentially act quickly to protect any remaining balances or intervene before the theft is finalized.
This narrow opportunity underscores the time-sensitive nature of hardware wallet compromises, where the difference between recovering assets and losing them entirely can come down to how fast a user responds.
Security researchers have repeatedly stressed that hardware wallet users should remain vigilant about the software and firmware they install, as well as the sources from which they download companion applications.
- Monitor wallet activity for any unauthorized outbound transactions.
- Act quickly if transactions remain unconfirmed on the network.
- Verify the authenticity of any wallet software and firmware updates.
Ongoing Concerns
The repeated waves of attacks highlight the persistent threats facing self-custody users, even those relying on hardware wallets long considered among the more secure options for storing Bitcoin. As investigations continue, affected users are being urged to review their holdings and take immediate protective measures where possible.
